![]() |
| Created by Kimberly Kline, API |
That duty begins with guarding the Personally Identifiable Information (PII) of your employees and clients.
Here we will discuss what information is considered PII, why it is important, and what you need to do now to safeguard it.
Specific Examples of PII are:
- Full Name (if not common)
- Home Address
- Date of Birth
- Social Security Number / National Identification Number
- Telephone Number
- Email Address (if private)
- Vehicle Registration Number
- Driver’s License Number
- Fingerprints or Handwriting
- Credit Card Numbers
- Genetic Information
- Login Name, Screen Name, or Handle (radio)
Examples of potential PII:
- Full Name (if common)
- Country, state, zip code, city of residence
- Age
- Gender or Race
- Name of School they attended or their Workplace
- Grades, Salary, or Job Position
- Criminal Record
- IP Address
That is why it is crucial to develop a sound policy concerning PII. Your policy should include the safe handling of PII, the proper training of your employees in what is PII and how to keep it safe, and the consequences of not following your policy.
As an employer, you are required to develop and implement a policy for the safe handling of PII. You must also include the rules of behavior expected, including the consequences for non-compliance.
All employees and contractors who have significant privacy information responsibilities must understand your PII policy. This includes any employees and contractors who work with PII as part of their job duties such as Human Resources staff, finance staff, or Managers / Supervisors.
![]() |
| Created by Kimberly Kline, API |
You should then consider “de-identifying” your records as much as possible. This means removing enough PII from any report or document so that the remaining information does not automatically identify an individual.
Another option is to “Anonymize” PII information. For example, you may consider substituting a code for the PII information (such as a name).
But the absolute best way to safeguard PII begins with controlling or limiting access to PII. This includes both physical and mobile access including cell phones, laptops, etc.. Curbing the number of people who come in contact with sensitive PII information is the easiest way to keep it safer and control how it is handled.
Careful consideration of the location of your PII records is also key. Keeping them onsite with limited accessibility is best. Any offsite or mobile storage creates vulnerability.
Your policy also needs to consider the confidential transmission of anything containing PII.
The final safeguarding part of your policy should be developing an auditing program to monitor for potential inappropriate access to PII or for a data breach.
Penalties may range from reprimand and retraining to suspension or removal. It should be noted that fines may also be levied on anyone found guilty of willful disclosure of PII.
The responsibility for properly training your employees and contractors who work with PII lies with you, the owner, and your managers. The best practice is to develop a thorough training program, make sure your workers follow the program, and frequently monitor the handling of PII.
This includes the previously mentioned limiting of access to PII. It also means the proper destroying of records physically, shredding for example, and digitally (sanitizing).
Creating sound PII handling procedures, along with a company Privacy Policy, makes sense. (Discover how to write a Privacy Policy for your Small Business here!)
Authored by



No comments:
Post a Comment
Thanks for visiting our website. Contact Us! We can answer your questions and offer you a consultation on how we can help You with your Hiring, Business, and Security Needs!
We also invite you to Subscribe. Just leave your email and you will get one new article each month with tips and information focused on You and Your Business!